ALUMINUM SARATOGA ... Tools ... BlackShades, BrittleBush, DarkComet, LastConn, Micropsia, NimbleMamba, PoisonIvy, QuasarRAT, XtremeRat
Blackshades
Blackshades is a Windows-focused remote access trojan that emerged around 2010 and was widely sold on underground forums at low cost, contributing to large-scale global abuse.
Profile source: Mallory opens in a new tabBlackshades
Family profile
Blackshades is a Windows-focused remote access trojan that emerged around 2010 and was widely sold on underground forums at low cost, contributing to large-scale global abuse. It enabled remote control of infected systems and was used to compromise and spy on hundreds of thousands of computers worldwide. Public reporting and law-enforcement actions have linked its development and sale to Alex Yücel and Michael Hogue.
Blackshades provides attackers with broad remote-administration and surveillance capabilities, including unauthorized access to victim machines, file access and modification, keystroke logging, webcam access, payload download and execution, and use of infected hosts as proxies. It has also been used to direct infected systems into distributed denial-of-service activity and has been described as capable of lock-screen style ransom behavior. Operators commonly paired it with obfuscation tools to reduce antivirus detection.
Distribution has been associated with malicious webpages, including drive-by download activity, as well as removable media such as USB devices. The malware was used both by opportunistic cybercriminals and in politically motivated surveillance. It was documented in campaigns targeting Syrian opposition figures, and it also figured in criminal sextortion cases involving covert webcam surveillance and theft of intimate material.
Blackshades became the subject of major international law-enforcement action, culminating in a 2014 coordinated crackdown spanning numerous countries and resulting in arrests, searches, and device seizures. Its history is frequently cited as a prominent example of a commodity RAT marketed as a purported administration tool but broadly used for unauthorized access, surveillance, and other criminal activity.
Capabilities
- Ddos
- Defense Evasion
- Exfiltration
- Keylogging
- Post Exploitation
- Spoofing
Reported operators
Threat actors
1 named in public reportingMITRE ATT&CK